2012/11/13

2012-Nov : Recent Security News

2012-11-04

Anonymous, VMWARE ESX Kernel 소스코드 해킹 및 소스코드 공개
http://thehackernews.com/2012/11/anonymous-leaks-vmware-esx-server-kernel.html#sthash.TywF4pcM.dpbs


Anonymous group member "Stun" announce the leak of VMware ESX Server Kernel source code via twitter today. The tweet reads,  "WILD LEAKY LEAK. FULL VMware ESX Server Kernel LEAKED LINK #Anonymous #AntiSec". VMware ESX is an enterprise-level computer virtualization product offered by VMware. The reason behind this wild leak by anonymous is that, Vmware continue producing on same level again and again which is not a good practice for better Security.

"Bullshitting people and selling crap. But it's time for Anonymous finally to deliver. Ofc VMware will try to make like this Kernel is old and isn't used in its recent products. But thanks god, there is still such as thing as reverse engineering that will prove it's true destiny." Hacker said.
- See more at: http://thehackernews.com/2012/11/anonymous-leaks-vmware-esx-server-kernel.html#sthash.TywF4pcM.dpuf (중략)

2012-11-04

@Doxbin를 포함한 해커가 Symantec  ImageShack 및 DB 서버 해킹 사실을 공개
http://thehackernews.com/2012/11/imageshack-server-and-symantec-database.html#_
Hackers hack into ImageShack server and expose all the files online, moreover Antivirus Company Symantec's portal also hacked by them and complete database of all 1000's of researchers dumped in a pastebin File. One of the hacker behind this hack avilable on twitter at @Doxbin.

Hacker expose content of few most important files of the server, like /etc/passwd , /etc/shadow , Content list of ImageShack Web directory (/home/image/www) and many more. Hacker claimed to use some zero day vulnerability in order to get into the server.

Whereas in Symantec case, hackers leak complete database from online portal. Database information includes Phone numbers, email, domain, password, Name, Username etc.

According to Hackers write up that exploit unknown zero-day bug of ZPanel used by Symantec to get into server. In same operation, hackers target CrytoCC website (http://kerpia.cryto.net/) also, which is a portal for independent developers. Its possibly a huge hack of the week and Possibly victim parties still unaware about the hack and data disclosed.
- See more at: http://thehackernews.com/2012/11/imageshack-server-and-symantec-database.html#sthash.gDfIMI56.dpuf 

2012-11-05

코카콜라, 2009년에 해킹당한 사실 숨겼다.
 : 악성 링크 삽입한 이메일을 임원들에게 보내는 방식, China Huiyuan Juice Group 인수 관련 자료를 얻기 위했던 것으로 알려져... 
 영문 뉴스 기사 : http://www.securityweek.com/coca-cola-hid-hack-2009-report
Officials at Coca-Cola reportedly hid the fact that the company was victimized in a breach in 2009.
According to Bloomberg News, the FBI approached the company when it learned hackers had stolen sensitive files about the company's $2.4 billion acquisition of China Huiyuan Juice Group, which eventually collapsed. The compromise was reportedly occurred via emails with malicious links that were sent to company executives.
In the first two days of the attack, a dozen tools were uploaded that allowed the theft of emails and documents, as well as the installation of a keystroke logger on the machine of a top executive in Hong Kong. The computer account passwords for other Coke executives were also stolen, allowing the attackers to move across the network more easily. (중략)
 한글 뉴스 기사 : http://www.etoday.co.kr/news/section/newsview.php?idxno=650213


2012-11-13

Antivirus의 전설로 알려진 (McAfee의 창립자) John McAfee가 살인혐의로 공개 수배...
http://www.securityweek.com/anti-virus-legend-john-mcafee-wanted-murder-belize
Anti-virus Legend John McAfee Wanted for Murder in Belize

BELIZE CITY - 
John McAfee, founder of the eponymous anti-virus company, is on the run for killing another US citizen in a resort town, Belizean police said Monday. Police raided McAfee's mansion on the island of Ambergris Caye, in northeastern Belize, late Sunday to question him about the murder of American Gregory Faull. But McAfee was nowhere to be found, said the head of the country's anti-organized crime brigade, Marco Vidal. McAfee "is wanted so that he can be interrogated for homicide," Vidal told reporters. Vidal's officers had searched McAfee's mansion several months ago looking for weapons and drugs, and detained him for several hours. (중략)
관련 추가 기사 (2012-11-15)

John McAfee는 자신을 대신해 이웃주민이 살해 당한 것이며, 자신도 죽일것이라고 자신의 무죄를 주장하며 여전히 도피중...
http://biz.chosun.com/site/data/html_dir/2012/11/15/2012111501881.html



2012-11-13

캐러비안에 있다는 한 섬 Guadeloupe의 국가 도메인이 해킹당해서 Twitter, Google을 포함 유명 도메인의 credentials이 유출

http://trickspak.blogspot.kr/2012/11/guadeloupe-national-domain-registrar.html


Guadeloupe is a Caribbean island located in the Leeward Islands, in the Lesser Antilles. Today a hacker going by name "UR0B0R0X" claimed to hack into the "Network Information Center Guadeloupe" (nic.gp), which is Guadeloupe National Domain registrar having control over domains of big companies like Google.gp, Paypal.gp, twitter.gp, Yahoo.gp,  and many more.
domains

Hacker claimed to hack server of nic.gp and leak credentials (encrypted) of 1271 Guadeloupe domains and user accounts including usernames, email addresses and phone numbers from server as shown via a paste-bin note. and complete database uploaded on a file sharing site.




..